Cru Inc develops specialized forensic data-capture and field-analysis devices, with a vulnerability footprint concentrated in the Ditto Forensic FieldStation product and its underlying firmware. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cru Inc over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-6881HIGH CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip co | Jan 7, 2014 | 10.0 | 41 | NO | YES |
CVE-2013-6884HIGH The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges. | Jan 7, 2014 | 10.0 | 39 | NO | YES |
CVE-2013-6883MEDIUM Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administr | Dec 17, 2013 | 6.8 | 27 | NO | YES |
CVE-2013-6882MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web scrip | Dec 17, 2013 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cru Inc.
Media articles that mention a CVE ID that affects a product developed by Cru Inc — matched by CVE ID, not by vendor name.